Real-time Security Situational Model for System State Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security tools can only operate retrospectively to detect security exploits due to the high computational cost of building comprehensive logs of system activities, placing them at a disadvantage against attackers.
Innovation Solution
A situational model representing the security-relevant state of monitored devices is constructed in real-time, allowing for the validation of state information and serving as a cache for computationally expensive or high-latency information, enabling real-time detection and response to security threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive logs of system activities are built for security analysis, then security exploit detection capability is improved, but computational cost and processing time increase significantly
Solution Approach 1:
The patent extracts only the essential security-relevant state information from comprehensive system logs, building a situational model that contains only critical security data rather than processing complete system activity logs. This extraction approach maintains security detection capability while dramatically reducing computational overhead.
Solution Approach 2:
The patent segments the security monitoring system into two parts: a lightweight situational model that tracks essential security state, and optional comprehensive logging for detailed analysis. This segmentation allows the system to maintain continuous security awareness with minimal computational cost while preserving the ability to perform deep analysis when needed.
2Reliability
If comprehensive logs of system activities are built for security analysis, then security exploit detection capability is improved, but real-time detection capability deteriorates
Solution Approach 1:
The patent performs preliminary action by continuously maintaining a situational model that pre-processes and structures security-relevant state information as events occur. This preliminary structuring eliminates the need for computationally intensive log processing during detection, enabling real-time security analysis while preserving comprehensive detection capability.
Solution Approach 2:
The patent creates a simplified copy of system state information in the situational model that contains only security-relevant data. This copy allows for rapid querying and analysis without requiring access to or processing of the complete system logs, thereby enabling real-time detection while maintaining thorough security monitoring.
3Loss of information
If events are written multiple times to logs with cross input/output boundaries, then completeness of security data is improved, but processing efficiency decreases
Solution Approach 1:
The patent introduces an intermediary situational model that receives and structures security-relevant information from system events. This intermediary layer processes events once and maintains a structured representation, eliminating the need for multiple log writes and cross-boundary processing while preserving complete security data for analysis.
Data Source
AI summary
A situational model representing of a state of a monitored device is described herein. The situational model is constructed with the security-relevant information in substantially real-time as execution activities of the monitored device associated with the security-relevant information are observed. The represented state may include a current state and a past state of the monitored device. Also, the situational model may be used to validate state information associated events occurring on the monitored device. Further, a remote security service may configure the monitored device, including configuring the situational model, and may build an additional situational model representing a state of a group of monitored devices.


